SonicWall Fixes Maximum-Severity Flaw in SMA1000 Remote Access Gateways
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious, tracked as CVE-2026-102255, is a server-side request forgery (SSRF) bug in WorkPlace, the portal users log in to. It can be reached before authentication, and SonicWall rates it 10.0 on the CVSS scale. An attacker who abuses it could "reach internal functionality and perform unauthorized operations," according to the company's October 6 advisory, which does not say which functions. SonicWall says it has no evidence that any of the four flaws is being used in attacks.
The other three flaws can only be used after logging in, and two of them are in the Appliance Management Console, where administrators configure the appliance. All four affect SMA1000 models 6210, 7210 and 8200v, including versions 12.4.3-03526 and 12.5.0-02952, which SonicWall named on September 1 as the fix for two earlier flaws. SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected. The hotfix is available from the MySonicWall portal, the appliance restarts after installation, and no workaround is listed.
This is the third time this year SonicWall has fixed a 10.0-rated, no-login SSRF flaw in WorkPlace. Earlier fixes in July and September came after SonicWall investigated attacks that exploited those flaws. This time, outside researchers reported the issues.